QuestionQ21

Incident Response Techniques

Question Image

Refer to the exhibit. Which two actions should be performed based on this information?

Choose two
  • A Update the AV to block any file with hash "cf2b3ad32a8a4cfb05e9dfc45875bd70".
  • B Block all emails sent from an @state.gov address.
  • C Block all emails with pdf attachments.
  • D Block emails sent from [email protected] with an attached pdf file with md5 hash "cf2b3ad32a8a4cfb05e9dfc45875bd70".
  • E Block all emails with subject containing "cf2b3ad32a8a4cfb05e9dfc45875bd70".
Explanation

A known malicious file hash can be added to antivirus or endpoint controls to prevent execution of that exact file. Email filtering can also block messages matching the identified sender pattern together with a PDF attachment having the specified MD5 hash. The observable does not support blanket blocking of all @state.gov senders or all PDF attachments.

Community Discussion

No comments yet. Be the first to start the discussion!